phishing

LinkedIn-themed phishing abuses Adobe’s A/B testing platform

LinkedIn-themed phishing abuses Adobe’s A/B testing platform 2026-05-29 at 14:08 By Zeljka Zorz A newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe. The attack from the victim’s perspective The attack starts with an email that looks, at first glance, like a routine business […]

LinkedIn-themed phishing abuses Adobe’s A/B testing platform Read More »

OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight

OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight 2026-05-27 at 09:24 By rohansinhacyblecom Executive Summary Cyble Research and Intelligence Labs (CRIL) has identified a novel Android banking trojan, dubbed OverlayPhantom, actively distributed in the wild via malicious URLs. The malware employs a two-stage infection chain, using a dropper application that impersonates trusted platforms, including

OverlayPhantom: The Android Banking Trojan Hiding in Plain Sight Read More »

Chinese phishing gangs grow into a force to be reckoned with

Chinese phishing gangs grow into a force to be reckoned with 2026-05-26 at 17:09 By Sinisa Markovic Chinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. The Google Threat Intelligence Group (GTIG) analyzed a dozen active PhaaS offerings operating in Chinese-language underground communities and found mature services, with several

Chinese phishing gangs grow into a force to be reckoned with Read More »

Microsoft 365 users targeted by new phishing threat that bypasses MFA

Microsoft 365 users targeted by new phishing threat that bypasses MFA 2026-05-22 at 12:17 By Sinisa Markovic Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in April 2026, Kali365 has been distributed through Telegram, allowing cybercriminals to obtain Microsoft 365 access tokens

Microsoft 365 users targeted by new phishing threat that bypasses MFA Read More »

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector 2026-05-20 at 17:16 By Zeljka Zorz Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the

Verizon DBIR: Vulnerability exploitation is the dominant initial access vector Read More »

PureLogs infostealer is stealing credentials worldwide

PureLogs infostealer is stealing credentials worldwide 2026-05-19 at 16:58 By Zeljka Zorz A phishing campaign is smuggling the powerful PureLogs information stealer onto targets’ Windows machines by hiding encrypted malicious payloads inside cat photos, Fortinet researchers discovered. The attack The attack starts with a phishing email containing a TXZ archive and using an invoice-themed lure

PureLogs infostealer is stealing credentials worldwide Read More »

Public Instagram posts provide raw material for AI phishing campaigns

Public Instagram posts provide raw material for AI phishing campaigns 2026-05-19 at 09:17 By Sinisa Markovic A handful of public Instagram posts can give attackers enough material to generate convincing phishing emails with GenAI. Research from the University of Texas at Arlington and Louisiana State University showed how public social media activity can be turned

Public Instagram posts provide raw material for AI phishing campaigns Read More »

201 arrested in INTERPOL disruption of phishing and fraud networks

201 arrested in INTERPOL disruption of phishing and fraud networks 2026-05-18 at 12:08 By Anamarija Pogorelec Operation Ramz, a cybercrime initiative coordinated by INTERPOL across the MENA region, focused on disrupting phishing campaigns, malware activity, and cyber scams that caused substantial financial losses across the region. The operation resulted in the arrest of 201 individuals

201 arrested in INTERPOL disruption of phishing and fraud networks Read More »

Signal responds to phishing attacks with new in-app security warnings

Signal responds to phishing attacks with new in-app security warnings 2026-05-13 at 16:08 By Sinisa Markovic Signal is adding new protections for users following recent phishing and social engineering attacks. In March, the FBI and CISA issued a warning stating that Signal had become a primary target of Russian intelligence-linked hackers. Dutch and German security

Signal responds to phishing attacks with new in-app security warnings Read More »

Over 500 Organizations Hit in Years-Long Phishing Campaign

Over 500 Organizations Hit in Years-Long Phishing Campaign 2026-05-11 at 07:22 By Ionut Arghire Victims span across the aviation, critical infrastructure, energy, logistics, public administration, and technology sectors. The post Over 500 Organizations Hit in Years-Long Phishing Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Over 500 Organizations Hit in Years-Long Phishing Campaign Read More »

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations 2026-05-05 at 17:45 By Eduard Kovacs The malicious emails claim to contain a conduct report and lure victims to a Microsoft phishing website that leverages AitM. The post Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations appeared first on SecurityWeek. This article is an excerpt

Microsoft Warns of Sophisticated Phishing Campaign Targeting US Organizations Read More »

Robinhood Vulnerability Exploited for Phishing Attacks

Robinhood Vulnerability Exploited for Phishing Attacks 2026-04-28 at 18:06 By Eduard Kovacs Legitimate-looking emails coming from Robinhood systems lured recipients to phishing websites. The post Robinhood Vulnerability Exploited for Phishing Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Robinhood Vulnerability Exploited for Phishing Attacks Read More »

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface 2026-04-23 at 14:17 By Kevin Townsend New analysis from Abnormal AI reveals how attackers have abandoned technical exploits to weaponize routine workflows and internal trust. The post The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface appeared first on SecurityWeek. This article

The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface Read More »

Cyberattack on French government agency triggers phishing alert

Cyberattack on French government agency triggers phishing alert 2026-04-22 at 19:55 By Sinisa Markovic France Titres, a French government agency, has disclosed a data breach that may have exposed user data from its online portal. France Titres, also known as the Agence nationale des titres sécurisés (ANTS), operates under the French Ministry of the Interior

Cyberattack on French government agency triggers phishing alert Read More »

Phishing reclaims the top initial access spot, attackers experiment with AI tools

Phishing reclaims the top initial access spot, attackers experiment with AI tools 2026-04-22 at 13:48 By Anamarija Pogorelec Phishing returned as the leading method attackers used to break into organizations in the first quarter of 2026, accounting for over a third of engagements where initial access could be determined, according to Cisco Talos. It is

Phishing reclaims the top initial access spot, attackers experiment with AI tools Read More »

Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency

Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency 2026-04-21 at 17:36 By Sinisa Markovic A British national tied to the Scattered Spider cybercrime group pleaded guilty to hacking multiple companies via SMS phishing and stealing over $8 million in virtual currency from US victims. Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded

Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency Read More »

AI platform ATHR makes voice phishing a one-person job

AI platform ATHR makes voice phishing a one-person job 2026-04-20 at 14:37 By Zeljka Zorz For $4,000 and a cut of the take, a lone criminal can now run a fully automated voice-phishing operation via ATHR, a plaform that spoofs emails alerts from Google, Microsoft, and Coinbase, buries a phone number in each message, and

AI platform ATHR makes voice phishing a one-person job Read More »

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks 2026-04-18 at 15:32 By Ionut Arghire Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption. The post Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks Read More »

Windows is getting stronger RDP file protections to fight phishing attacks

Windows is getting stronger RDP file protections to fight phishing attacks 2026-04-16 at 01:19 By Sinisa Markovic Microsoft has introduced new Windows protections starting with the April 2026 security update to reduce phishing attacks that abuse Remote Desktop (.rdp) files. With these updates, the Remote Desktop Connection app displays stronger warning dialogs before a connection

Windows is getting stronger RDP file protections to fight phishing attacks Read More »

Scroll to Top